---
id: CVE-2025-37735
title: >-
  Improper preservation of permissions in Elastic Defend on Windows hosts can
  lead to arbitrary files on the system being deleted by the Defend service
  running as SYSTEM
summary: >-
  Improper preservation of permissions in Elastic Defend on Windows hosts can
  lead to arbitrary files on the system being deleted by the Defend service
  running as SYSTEM. In some cases, this could result in local privilege
  escalation.
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-281
published: '2025-11-06'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-37735'
references:
  - url: >-
      https://discuss.elastic.co/t/elastic-defend-8-19-6-9-1-6-and-9-2-0-security-update-esa-2025-23/383272
    label: security@elastic.co
tags:
  - nvd
epss: 0.00139
epssPercentile: 0.02782
ingestedAt: '2026-10-07T21:54:14.927Z'
---

## Overview

Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the Defend service running as SYSTEM. In some cases, this could result in local privilege escalation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
